Skip to content

Root-Cause Analysis (RCA)

Definition

A structured method for identifying the underlying systemic cause of a failure rather than its immediate trigger. Common techniques in incident review include five-whys, fishbone (Ishikawa) diagrams, and fault-tree analysis. The goal is to find the cause whose correction prevents recurrence, not the cause that was most visible during the incident.

Goal
Identify underlying systemic cause, not the immediate trigger
Common techniques
Five-whys, fishbone (Ishikawa) diagram, fault-tree analysis
Applied in
Post-incident review and lessons-learned processes
Success criterion
Correcting the found cause prevents recurrence

Common questions

Why does RCA focus on the least visible cause rather than the most obvious one?+

The most visible trigger, such as a single misconfigured server, is often just the last link in a longer chain of contributing factors like inadequate change review or missing monitoring, and fixing only the visible trigger leaves the systemic weakness in place for a repeat incident.

How does the five-whys technique avoid stopping at a superficial answer?+

It repeatedly asks why the preceding cause occurred, typically five times, pushing the analysis past the first plausible explanation until it reaches a process, policy, or design gap that management can actually correct.

What is the risk of treating RCA as a blame-assignment exercise?+

If staff fear personal blame, they tend to withhold details during the review, which produces an incomplete causal chain and an RCA that identifies a scapegoat rather than the systemic condition that actually needs fixing.

Related terms

Action Item
A specific, time-bound improvement task generated by a post-incident finding. An action item has a named owner, a target completion date, a...
Blameless Post-Mortem
A cultural approach to post-incident review, popularised in site reliability engineering, in which the analysis focuses on systemic and process failures rather...
Lessons-Learned Register
A persistent record, maintained by the security programme, that links each post-incident action item to the originating incident, tracks its status, and...
Post-Incident Activity
The NIST SP 800-61 label for the final phase of the incident response lifecycle. It encompasses evidence retention, lessons-learned meetings, and the...
Timeline Reconstruction
The process of ordering digital events from multiple sources into a single chronological account. Requires normalising all timestamps to a common reference...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.